Skip to content

Batch #3 - August 2026 (8 advisories · 8 critical · 8 unauth)

Choose a tag to compare

@Exploit-Garbage Exploit-Garbage released this 09 Aug 11:52
· 6 commits to main since this release

Batch #3 — August 2026

8 advisories · 8 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.

Third batch — expanding coverage into data platforms, SCADA, BI/reporting, and IoT/embedded systems. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.

# Product Affected Version CVSS Class Advisory & PoC
1 Confluent Platform 7.9.1-ce 9.8 Unauth RCE (Root) ksqlDB CREATE SINK CONNECTOR → RCE
2 Ontotext GraphDB 11.4.3 9.8 Unauth RCE (Root) .pie Ruleset Prefix Injection → RCE
3 ObjectDB 2.9.5 9.8 Unauth RCE (Root) JDOQL Filter Injection → RCE
4 Wyn Enterprise 9.1.00145.0 9.8 Unauth RCE (Root) Token Forgery + Zip-Slip + Provider Load → RCE
5 MAPS SCADA 4.0.5.5 9.8 Unauth RCE (SYSTEM) BinaryFormatter Deserialization → RCE
6 DataStax Enterprise 6.8.49 9.8 Unauth RCE Gremlin-Groovy Sandbox Bypass → RCE
7 nanoDLP stable #10729 9.8 Unauth RCE (Root) G-code Injection → RCE
8 iMonnit Express 4.0.5.5 9.8 Unauth RCE (SYSTEM) Auth Bypass + Path Traversal + Plugin Load → RCE

Highlights

  • 8 critical (CVSS ≥ 9.0) · 8 unauthenticated
  • Notable: Confluent ksqlDB → cron root RCE, DataStax Gremlin-Groovy sandbox bypass, and an OT/SCADA SYSTEM RCE (MAPS SCADA)
  • Attack classes: code injection, JDOQL injection, deserialization, sandbox bypass, G-code injection, plugin dynamic loading

Running total

35 advisories · 26 vendors · 29 critical · 28 unauthenticated · all with reproducible PoC.

Next drop: weekly → expanding into ICS / SCADA, energy, and aerospace.

Star to bookmark · 👁 Watch for the next batch · 🌐 https://0day-rubbish.com/blog